foundry-mari

maintainer adro · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary installer (.run file) from thefoundry.s3.amazonaws.com and executes it during the package() phase. While The Foundry (now Foundry) is a legitimate commercial software vendor and S3 is a plausible distribution channel for them, this is not the canonical foundry.com download domain. The .run installer is executed directly with --accept-eula and --prefix flags, meaning arbitrary code from that binary runs during packaging. The md5sums check provides weak integrity assurance (MD5 is cryptographically broken). The real concern is that an S3 bucket URL is less stable and verifiable than a primary vendor domain — bucket names can be squatted or misconfigured — and executing a prebuilt binary installer is a genuine supply-chain risk. This is a legitimate medium: not clearly malicious, but an executed binary from a non-primary host with weak integrity checking.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=(https://thefoundry.s3.amazonaws.com/products/mari/releases/$pkgver/Mari$pkgver-linux-x86-release-64.run)
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary installer (.run file) from thefoundry.s3.amazonaws.com and executes it during the package() phase. While The Foundry (now Foundry) is a legitimate commercial software vendor and S3 is a plausible distribution channel for them, this is not the canonical foundry.com download domain. The .run installer is executed directly with --accept-eula and --prefix flags, meaning arbitrary code from that binary runs during packaging. The md5sums check provides weak integrity assurance (MD5 is cryptographically broken). The real concern is that an S3 bucket URL is less stable and verifiable than a primary vendor domain — bucket names can be squatted or misconfigured — and executing a prebuilt binary installer is a genuine supply-chain risk. This is a legitimate medium: not clearly malicious, but an executed binary from a non-primary host with weak integrity checking.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Adrià Cabello <adro.cc79 at protonmail dot com>
2pkgname=foundry-mari
3_pkgver_major=7
4_pkgver_minor=0
5_pkgver_build=1
6pkgver=${_pkgver_major}.${_pkgver_minor}v${_pkgver_build}
7pkgrel=1
8pkgdesc="3D Painting Industry Standard Tool for complex assets"
9arch=('x86_64')
10license=('Custom: The Foundry')
11provides=('mari')
12url="https://www.foundry.com/products/mari"
13source=(https://thefoundry.s3.amazonaws.com/products/mari/releases/$pkgver/Mari$pkgver-linux-x86-release-64.run)
14md5sums=('0e54fdbb0396982964227dc7680e1513')
15
16package() {
17 mkdir -p "${pkgdir}/opt/mari"
18 mkdir -p "${pkgdir}/usr/bin"
19
20 chmod +x Mari$pkgver-linux-x86-release-64.run
21
22 ./Mari$pkgver-linux-x86-release-64.run --prefix=${pkgdir}/opt/mari --accept-eula
23
24 ln -s "/opt/mari/mari" "${pkgdir}/usr/bin/mari"
25}
26

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion